• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Malware Exploiting 9Hits, Turns Docker Servers into Crypto Miners

18 January 2024
in Mining
Reading Time: 3 mins read
A A
0
Malware Exploiting 9Hits, Turns Docker Servers into Crypto Miners
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Cybercriminals are targeting vulnerable Docker servers by deploying two containers: a standard XMRig miner and the 9Hits viewer application—an automated traffic exchange system.

Cado Security researchers have discovered a new campaign targeting vulnerable Docker servers, deploying two containers – a regular XMRig miner and the 9hits viewer application. This is the first documented case of malware deploying the 9Hits Traffic Exchange viewer application as a payload.

For your information, 9hits is a platform where members buy credits for traffic generated on their website and can run the viewer app to visit requested websites in exchange for credits.

Researchers suspect that the attackers discovered the honeypot via Shodan or a similar service, as their IP isn’t included in common abuse databases, or they may be using a different server for scanning.

Further probing revealed that the attacker is likely using a script to set the DOCKER_HOST variable and run the regular CLI to compromise the server. They fetch off-the-shelf images from Dockerhub for their 9hits and XMRig software, a common attack vector for campaigns targeting Docker.

Generally, attackers use a generic Alpine image to break out of a container and run malware on the host. In this campaign, however, they do not try to exit the container and run it with a predetermined argument.

The spreader initiates the infection using a custom command to invoke a Docker container, including configuration/session identifiers. The nh.sh process is the entry point, and after the attacker adds their session token, it allows the 9hits app to authenticate with their servers and fetches a list of sites to visit. Once the app has visited the site, the session token owner is awarded a credit on the 9hits platform.

It is worth noting that the session token system is designed to work in untrusted contexts, allowing the app to be run in illegitimate campaigns without the risk of the attacker’s account being compromised.

9hits, a headless Chrome app, is used to visit various websites, including adult and pop-up sites. In 2017, Chrome 59 introduced Headless mode, allowing users to run the browser in an unattended environment without visible UI, making it popular for browser automation with projects like Puppeteer or ChromeDriver.

According to Cado Security’s blog post, interestingly, the attacker disabled the app’s ability to visit crypto-related sites. The -o option in XMRig deployments specifies a mining pool, typically a public pool with the owner’s wallet address, but in this case, it appears private, preventing campaign statistics analysis.

Further, as seen in the image below, the dscloud domain is used for dynamic DNS, updated by the Synology server with the attacker’s IP. The address resolves to 2736.82.56, the same IP that infected the honeypot.

Exposure to Docker hosts remains a common entry vector for attackers, emphasizing the importance of maintaining system security to prevent malicious use of systems. The campaign significantly impacts compromised hosts by exhausting CPU resources, causing legitimate workloads to fail.

Additionally, it could potentially leave a remote shell on the system, causing a more serious breach. This highlights the ongoing trend of attackers seeking new strategies to exploit compromised hosts.

RELATED ARTICLES

  1. Change your password: Docker suffers breach; 190k users affected
  2. Hackers Exploit Adobe ColdFusion Vulnerabilities to Deploy Malware
  3. Threat actors hijacking Bitbucket and Docker Hub for Monero mining
  4. OracleIV DDoS Botnet Malware Targets Docker Engine API Instances
  5. Kinsing Crypto Malware Targets Linux Systems via Apache ActiveMQ Flaw



Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: 9HitscryptoDockerExploitingMalwareMinersServersTurns
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Experts See Solana Outperforming ETH by 500% this Season

Next Post

Arthur Hayes backs Solana; Redditors exploring Dogecoin rival

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Arthur Hayes backs Solana; Redditors exploring Dogecoin rival

Arthur Hayes backs Solana; Redditors exploring Dogecoin rival

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana Ecosystem Trends Among Top Gainers as Alpenglow Discussions Increase – Coinspeaker

Solana Ecosystem Trends Among Top Gainers as Alpenglow Discussions Increase – Coinspeaker

12 September 2025
3 Low-Cap Altcoins Showing Strong Accumulation Trends

3 Low-Cap Altcoins Showing Strong Accumulation Trends

12 September 2025
Dogecoin and BNB Rise as Bitcoin, Ethereum Hit Highest Prices This Month – Decrypt

Dogecoin and BNB Rise as Bitcoin, Ethereum Hit Highest Prices This Month – Decrypt

12 September 2025
Streamer Gets Slapped by Gym Influencer Bradley Martyn, Pumping Solana Token – Yahoo Finance

Streamer Gets Slapped by Gym Influencer Bradley Martyn, Pumping Solana Token – Yahoo Finance

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana Ecosystem Trends Among Top Gainers as Alpenglow Discussions Increase – Coinspeaker
  • 3 Low-Cap Altcoins Showing Strong Accumulation Trends
  • Dogecoin and BNB Rise as Bitcoin, Ethereum Hit Highest Prices This Month – Decrypt
  • Streamer Gets Slapped by Gym Influencer Bradley Martyn, Pumping Solana Token – Yahoo Finance
  • Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 116,091.00
  • ethereumEthereum (ETH) $ 4,698.63
  • xrpXRP (XRP) $ 3.11
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 241.47
  • bnbBNB (BNB) $ 925.93
  • usd-coinUSDC (USDC) $ 0.999808
  • dogecoinDogecoin (DOGE) $ 0.277971
  • staked-etherLido Staked Ether (STETH) $ 4,690.10
  • cardanoCardano (ADA) $ 0.915831
  • tronTRON (TRX) $ 0.352102
  • wrapped-stethWrapped stETH (WSTETH) $ 5,695.56
  • chainlinkChainlink (LINK) $ 25.16
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 5,066.43
  • hyperliquidHyperliquid (HYPE) $ 55.16
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 116,081.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.72
  • stellarStellar (XLM) $ 0.403881
  • wrapped-eethWrapped eETH (WEETH) $ 5,047.58
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.01
  • avalanche-2Avalanche (AVAX) $ 28.73
  • bitcoin-cashBitcoin Cash (BCH) $ 598.37
  • wethWETH (WETH) $ 4,700.22
  • hedera-hashgraphHedera (HBAR) $ 0.245222
  • litecoinLitecoin (LTC) $ 117.84
  • leo-tokenLEO Token (LEO) $ 9.58
  • crypto-com-chainCronos (CRO) $ 0.254672
  • the-open-networkToncoin (TON) $ 3.22
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • usdsUSDS (USDS) $ 0.999583
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 116,142.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.32
  • whitebitWhiteBIT Coin (WBT) $ 44.36
  • uniswapUniswap (UNI) $ 10.20
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.207930
  • mantleMantle (MNT) $ 1.70
  • ethenaEthena (ENA) $ 0.773934
  • moneroMonero (XMR) $ 283.08
  • aaveAave (AAVE) $ 320.91
  • pepePepe (PEPE) $ 0.000012
  • bitget-tokenBitget Token (BGB) $ 4.94
  • daiDai (DAI) $ 0.999914
  • okbOKB (OKB) $ 200.03
  • memecoreMemeCore (M) $ 2.19
  • jito-staked-solJito Staked SOL (JITOSOL) $ 297.09
  • nearNEAR Protocol (NEAR) $ 2.80
  • ondo-financeOndo (ONDO) $ 1.10